tashatuvango - Fotolia

Crest introduces AI security standards for service providers

Industry organisation reacts to the growing need for independently verified standards surrounding artificial intelligence security

Standards specialist Crest has cut the ribbon on a range of artificial intelligence (AI) additions that it offers to service providers as it looks to provide independent metrics customers can judge their suppliers against.

Applications are open for existing Crest members as well as those across the channel that want to get assessed and verified, and which have met independent standards around providing AI security.

The standards have been designed in collaboration with the industry, and the standards group intends to keep ensuring they remain relevant through its AI Working Group.

The decision to include more AI comes as security vendors, partners and customers continue to accelerate their inclusion and adoption of the technology. Research has consistently shown that fears of data breaches connected with using AI are a number one concern.

The latest AI security 2026 report from Sophos last week underlined how the cyber criminal community were using AI to increase the speed and volume of attacks to make life harder for those aiming to protect data. The technology meant that it was now possible for bad elements to run attack workflows in days rather than weeks craning up the pressure on defence systems.

Crest said the move marked a shift from being able to claim AI security expertise to something more formal, which would benefit both service providers and customers.

“AI adoption is outpacing governance, and we are here to fix that,” said Nick Benson, CEO of Crest. “We recognise that buyers are increasingly demanding that AI-enabled services are independently assured. In such a fast-moving space, there was no time to waste. We believe these new additions to our standards will provide a practical, enforceable framework to regain the market’s trust.”

The standards group provided a range of reactions from members, with all welcoming the decision to include more AI coverage. William Wright, CEO of Closed Door Security, echoed the views of many: “Crest’s new standard comes at a critical time as organisations are becoming increasingly dependent on AI. Advanced AI systems are steadily moving towards becoming critical infrastructure, and it is essential that organisations are confident in the security surrounding them.

“With them now being adopted to support security operations and to identify and remediate vulnerabilities, they require a framework approach for responsible usage that this new standard brings.”

Others across the managed services world have also espoused the growing importance of trust as a key feature of any successful relationship between a service provider and a customer.

In a market where there has been a lack of standards, partners have often had to use vendor accreditation schemes as the main method of differentiating from the pack and underlining their security capabilities to existing and potential customers.

Earlier this year, Brother UK’s Tech trust survey underlined how buying decisions pivoted around the relationships between customers, partners and vendors.

Phil Jones, managing director at Brother UK, said it was clear that brand mattered to customers, with the quality of products providing reassurance to users: “IT leads put their neck on the line every time they introduce new technology into their business. They need to know it will perform and add commercial benefit – whether that’s laptops, AV, software systems or printers – without creating disruption or support downtime.”

Read more on Data Protection Services